📦 Zzcms

by Zzcms

🔍 What is Zzcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22957

CRITICAL CVSS 9.8 Jan 31, 2025

An unauthenticated SQL injection vulnerability in ZZCMS front-end allows attackers to execute arbitrary SQL commands against the database. This affects all ZZCMS installations version 2023 and earlier...

CVE-2024-52724

CRITICAL CVSS 9.8 Dec 2, 2024

ZZCMS 2023 contains a SQL injection vulnerability in the /q/show.php endpoint that allows attackers to execute arbitrary SQL commands. This affects all deployments of ZZCMS 2023 that have this endpoin...

CVE-2023-50104

CRITICAL CVSS 9.8 Dec 29, 2023

ZZCMS 2023 has an unauthenticated file upload vulnerability that allows attackers to upload malicious files and execute arbitrary code on the server. This affects all systems running ZZCMS 2023 with t...

CVE-2019-12349

CRITICAL CVSS 9.8 Jun 2, 2022

This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands through the id parameter in /admin/dl_sendsms.php. This affects all zzcms 2019 installations with the ...

CVE-2019-12351

CRITICAL CVSS 9.8 Jun 2, 2022

This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands via the id parameter in dl/dl_print.php. Any system running the vulnerable version of zzcms is affecte...

CVE-2021-42945

CRITICAL CVSS 9.8 Dec 15, 2021

This SQL injection vulnerability in ZZCMS 2021 allows attackers to execute arbitrary SQL commands through the askbigclassid parameter in /admin/ask.php. Attackers can potentially read, modify, or dele...

CVE-2021-43703

CRITICAL CVSS 9.8 Dec 9, 2021

This vulnerability allows unauthenticated attackers to bypass authentication controls in zzcms by disabling JavaScript and directly accessing admin.php. Any organization running vulnerable versions of...

CVE-2019-12348

CRITICAL CVSS 9.8 May 24, 2021

This SQL injection vulnerability in zzcms 2019 allows attackers to execute arbitrary SQL commands through the daohang or img POST parameters in user/ztconfig.php. This affects all systems running vuln...

CVE-2020-23426

CRITICAL CVSS 9.8 Apr 8, 2021

CVE-2020-23426 is a privilege escalation vulnerability in zzcms 201910 that allows attackers to gain unauthorized administrative access through the /user/adv.php endpoint. This affects all users runni...

CVE-2025-0565

HIGH CVSS 7.3 Jan 19, 2025

CVE-2025-0565 is a critical SQL injection vulnerability in ZZCMS 2023 that allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in /index.php. This affects all ZZCMS 2023 i...

CVE-2024-7927

HIGH CVSS 7.3 Aug 19, 2024

This critical vulnerability in ZZCMS 2023 allows remote attackers to perform path traversal attacks via the skin[] parameter in /admin/class.php?dowhat=modifyclass. This could enable unauthorized file...

CVE-2023-36162

HIGH CVSS 8.8 Jul 3, 2023

This CSRF vulnerability in ZZCMS allows attackers to trick authenticated administrators into performing unauthorized actions, such as adding new admin accounts. It affects all ZZCMS versions up to and...

CVE-2019-12352

HIGH CVSS 8.8 Jun 17, 2022

This SQL injection vulnerability in zzcms 2019 allows attackers with dls_print authority to execute arbitrary SQL commands via the dlid cookie in /dl/dl_sendmail.php. This can lead to data theft, modi...

CVE-2019-12354

HIGH CVSS 7.2 Jun 17, 2022

This SQL injection vulnerability in zzcms 2019 allows authenticated administrators to execute arbitrary SQL commands through the /admin/showbad.php endpoint via the id parameter. Attackers with admin ...

CVE-2019-12356

HIGH CVSS 8.8 Jun 17, 2022

This SQL injection vulnerability in zzcms 2019 allows authenticated attackers with download authority to execute arbitrary SQL commands through the id parameter in /user/dls_download.php. This affects...

CVE-2019-12358

HIGH CVSS 8.8 Jun 17, 2022

This SQL injection vulnerability in zzcms 2019 allows attackers with dls_print authority to execute arbitrary SQL commands via the dlid cookie in /dl/dl_sendsms.php. This could lead to data theft, mod...

CVE-2021-40281

HIGH CVSS 8.8 Dec 9, 2021

This SQL injection vulnerability in zzcms allows attackers to execute arbitrary SQL commands through the user registration functionality. It affects all zzcms installations running vulnerable versions...

CVE-2021-40280

HIGH CVSS 7.2 Dec 9, 2021

An SQL injection vulnerability exists in zzcms versions 8.2, 8.3, 2020, and 2021 through the id parameter in admin/dl_sendmail.php. This allows attackers to execute arbitrary SQL commands on the datab...

CVE-2025-14837

MEDIUM CVSS 4.7 Dec 18, 2025

This vulnerability in ZZCMS 2025 allows remote attackers to inject malicious code through the 'icp' parameter in the backend site configuration module. It affects administrators who can access the /ad...

CVE-2025-13171

MEDIUM CVSS 6.3 Nov 14, 2025

This SQL injection vulnerability in ZZCMS 2023 allows remote attackers to execute arbitrary SQL commands through the 'keyword' parameter in /admin/wangkan_list.php. Attackers can potentially access, m...

CVE-2025-1949

MEDIUM CVSS 4.3 Mar 4, 2025

This vulnerability in ZZCMS 2025 allows cross-site scripting (XSS) attacks through manipulation of the $_SERVER['PHP_SELF'] parameter in the /3/ucenter_api/code/register_nodb.php file. Attackers can i...

CVE-2024-10293

MEDIUM CVSS 6.3 Oct 23, 2024

This critical vulnerability in ZZCMS 2023 allows remote attackers to upload arbitrary files without restrictions via the Ebak_SetGotoPak function. Attackers can exploit this to upload malicious files ...

CVE-2024-10291

MEDIUM CVSS 6.3 Oct 23, 2024

This critical SQL injection vulnerability in ZZCMS 2023 allows remote attackers to execute arbitrary SQL commands through the phome parameter in the Ebak_DoExecSQL/Ebak_DotranExecutSQL functions. Atta...

CVE-2024-10290

MEDIUM CVSS 5.3 Oct 23, 2024

This vulnerability in ZZCMS 2023 allows remote attackers to access sensitive information through the file 3/qq-connect2.0/API/com/inc.php. The information disclosure could expose system details, confi...

CVE-2024-44818

MEDIUM CVSS 5.4 Sep 4, 2024

This is a reflected Cross-Site Scripting (XSS) vulnerability in ZZCMS that allows attackers to inject malicious scripts via the HTTP_Referer header. When exploited, it can lead to session hijacking, c...

CVE-2024-44820

MEDIUM CVSS 6.1 Sep 4, 2024

This vulnerability allows unauthenticated attackers to access sensitive PHP environment information by visiting a specific URL with a query parameter. It affects ZZCMS v.2023 and earlier versions. The...

CVE-2024-7925

MEDIUM CVSS 4.3 Aug 19, 2024

This vulnerability in ZZCMS 2023 allows remote attackers to disclose sensitive information by manipulating the 'phome' parameter in the 'eginfo.php' file. The information leak could expose system deta...

CVE-2024-43005

MEDIUM CVSS 4.7 Aug 16, 2024

A reflected cross-site scripting (XSS) vulnerability in ZZCMS v2023 allows attackers to inject malicious scripts via the dl_liuyan_save.php component. When exploited, this enables arbitrary code execu...

CVE-2024-43009

MEDIUM CVSS 4.7 Aug 16, 2024

This reflected XSS vulnerability in ZZCMS allows attackers to inject malicious JavaScript via the HTTP Referer header. When exploited, it can execute arbitrary code in victims' browsers, potentially l...

CVE-2025-14836

LOW CVSS 2.7 Dec 17, 2025

This vulnerability in ZZCMS 2025 allows attackers to store user data in cleartext on disk through the /reg/user_save.php file. Remote exploitation is possible, potentially exposing sensitive informati...